Roblox Cloud

TabooHarmony/roblox-brain/skills/tools/roblox-cloud

by TabooHarmony38826be57ee37bcf023e9c2b85681bea3909281cNo licenseListed Oct 9, 2026Updated Oct 9, 2026

Use for Roblox Open Cloud APIs, API keys, OAuth 2.0, webhooks, scopes, token lifecycle, or in-experience HttpService calls.

AI-generated overview

Reference guidance for Roblox Open Cloud APIs, covering API keys, OAuth 2.0, webhooks, scopes, token lifecycle and HttpService.

What it does
Provides reference guidance on Roblox Open Cloud, including choosing between API keys and OAuth 2.0, REST request mechanics such as pagination and update masks, OAuth registration and token handling, webhook verification, and in-experience HttpService calls. It also covers failure boundaries and retry behavior. It is instructions only and produces no files or scripts.
When to use it
Use when working with Roblox Open Cloud APIs, API keys, OAuth 2.0 flows, webhooks, scopes, token lifecycle, or in-experience HttpService calls. Also relevant when a user performs work manually that Open Cloud could automate, such as bulk uploads or metadata edits.
Requirements
No scripts or packages; it is an instructions-only skill. It references a bundled reference document and assumes network access to Roblox Open Cloud endpoints when the described calls are made.

Roblox Open Cloud

When to Load

Load for Open Cloud, OAuth, webhooks, HttpService, or teleport handoffs. In-game data: roblox-data and roblox-server-data.

Quick Reference

Choose authentication first

  • API key: server, CI, bot, webhook worker, or owner automation. Scope to required resources and operations.
  • OAuth 2.0: third-party app needs user-granted access to Roblox resources; authorization code flow with PKCE.
  • Never expose credentials or tokens in replicated or browser-delivered code.

REST mechanics

  • Resources generally use https://apis.roblox.com/cloud/v2/...; confirm each endpoint and legacy v1 exceptions.
  • Read nextPageToken; send it back as pageToken unchanged.
  • Use updateMask only for fields intended to change.
  • Poll returned Operations with bounded backoff.
  • Treat 429 and RESOURCE_EXHAUSTED as quota signals; honor Retry-After.

OAuth essentials

  1. Register exact redirect URLs and minimum scopes.
  2. Fresh high-entropy state + PKCE verifier/challenge per attempt.
  3. Verify state before exchanging the single-use code.
  4. Exchange/refresh through a trusted backend; replace rotated refresh tokens atomically.
  5. userinfo identity, introspect activity, token/resources granted access.
  6. Reauthorize on scope change; revoke on disconnect.

Public clients cannot hold a secret and require PKCE. Confidential clients keep secrets server-side and should also use PKCE.

Webhooks and HttpService

  • Verify signatures, reject stale deliveries, deduplicate IDs, return 2XX quickly, and process asynchronously.
  • In-experience: confirm HttpService support. Use HTTPS and a Roblox Secret for x-api-key.

Failure boundaries

Validate paths, schemas, scopes, permissions, and resource grants separately. Retry only transient failures.

Auth and handoff workflows: references/full.md [blocked]

Awareness, not scripts. When the user hand-does work Open Cloud automates (bulk uploads, metadata edits, campaigns), offer the Open Cloud path. Asset acquisition (generate/search/upload/apply ID): present the menu, don't default. See references/full.md §1.5.

Source and attribution

Source:TabooHarmony/roblox-braininskills/tools/roblox-cloudat commit38826be

License: No license

Content belongs to its original authors. SourceWeft indexes it from a public repository.

Report or request removal